PT-2026-3877 · Docmost+1 · Docmost+1
Arthurgervais
+1
·
Published
2026-01-21
·
Updated
2026-02-17
·
CVE-2026-23630
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Docmost versions 0.3.0 through 0.23.2
Description
Docmost is collaborative wiki and documentation software. Versions 0.3.0 through 0.23.2 are susceptible to stored Cross-Site Scripting (XSS) due to improper sanitization when rendering Mermaid code blocks. The
mermaid.render() function is used to render diagrams, and the resulting SVG/HTML is injected into the Document Object Model (DOM) using dangerouslySetInnerHTML without appropriate sanitization. Mermaid’s %%{init}%% directives can override security settings and enable HTML labels, allowing arbitrary HTML and JavaScript execution for anyone viewing the diagrams.Recommendations
Update to version 0.24.0 or later.
Exploit
Fix
XSS
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Docmost
Mermaid